CVE-2014-0015: Haxx Curl
Medium severity, CVSS 4.0. EPSS: 5.6% chance of exploitation in the next 30 days.
cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method is enabled, re-uses NTLM connections, which might allow context-dependent attackers to authenticate as other users via a request.
Affected products
- Haxx Curl: version 7.10.6 only; version 7.10.7 only; version 7.10.8 only; version 7.11.0 only; version 7.11.1 only; version 7.11.2 only; …
- Haxx Libcurl: version 7.10.6 only; version 7.10.7 only; version 7.10.8 only; version 7.11.0 only; version 7.11.1 only; version 7.11.2 only; …
Published 2014-02-02. Last modified 2026-06-17.